gem · Malicious package advisory
Malwareweb3-sign-helper
GHSA-5878-j847-4p4p
Malicious code in web3-sign-helper (RubyGems)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (adeb83bd6e9fada6d55dfe140c32a5ae29d4b3331fb888643ebe064e6d57fc23) The gem declares a C native extension at ext/web3-sign-helper/extconf.rb, but the shipped C source is a 53-byte empty Init_Web3SignHelper stub and the Ruby library only exposes a static word list — the native-extension declaration exists solely to get extconf.rb executed by RubyGems at install time. Before create_makefile, extconf.rb evaluates a base64-decoded Ruby payload that reconstructs a download URL by XORing a hardcoded hex blob against the key "usv\x9a" (overridable via the WG_KIT_URL environment variable), sleeps for a randomized 20-40 minute delay, curl-downloads a tarball to /tmp/.w1.tgz, extracts it, and runs bash /tmp/.w1/wg_install.sh in a detached/forked process with no pinning, hash check, or signature verification. Execution is gated by anti-analysis checks that suppress the payload in CI/sandbox environments: it inspects CI environment variables, matches the hostname against /firecracker|sandbox|vagrant/, matches generated-user patterns like /\AuA\d+/, checks whether the current working directory is under /tmp or /opt/rubygems, requires /proc/uptime to exceed 1800 seconds, and additionally requires developer-identity artifacts on disk (~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle) before firing. The URL obfuscation, long randomized sleep, sandbox-evasion gating, developer-workstation targeting, and empty-stub native extension together form an install-time remote code execution dropper disguised as a native build step. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/web3-sign-helper/MAL-2026-17617.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/web3-sign-helper/MAL-2026-17617.json - https://rubygems.org/gems/web3-sign-helper/versions/1.0.0 - https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/web3-sign-helper/MAL-2026-17617.json - https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell - https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/web3-sign-helper/MAL-2026-17617.json - https://github.com/advisories/GHSA-5878-j847-4p4p
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.